Boletim Diário de Segurança

Edição mais recente: 1 de outubro de 2026

Agregado automaticamente, sem curadoria humana, a partir de fontes públicas: CISA KEV, NVD, EQSTLab e VEXDay. Cada alerta leva à sua fonte oficial.

1 de outubro de 2026

Edição em andamento · atualizada em 01/10/2026, 10:13

Exploração ativa0
Com PoC0
Críticas15Altas68Outras10

15 alertas em críticas de 93 nesta edição.

Críticas

15
Crítica · CVSS 10.0
NVD

CVE-2026-101148

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files...

Crítica · CVSS 9.8
NVD

CVE-2026-103244

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate...

Crítica · CVSS 9.8
NVD

CVE-2026-75957

The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible...

Crítica · CVSS 9.8
NVD

CVE-2026-15989

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that...

Crítica · CVSS 9.8
NVD

CVE-2025-41753

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to...

Crítica · CVSS 9.8
NVD

CVE-2026-82829

Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.

Crítica · CVSS 9.8
NVD

CVE-2026-82827

Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.

Crítica · CVSS 9.8
NVD

CVE-2026-82825

Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects...

Crítica · CVSS 9.8
NVD

CVE-2026-82824

Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.

Crítica · CVSS 9.3
NVD

CVE-2026-103655

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system...

Crítica · CVSS 9.3
NVD

CVE-2026-76142

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Crítica · CVSS 9.1
NVD

CVE-2026-103264

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device...

Crítica · CVSS 9.1
NVD

CVE-2026-92966

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running...

Crítica · CVSS 9.0
NVD

CVE-2026-103255

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and...

Crítica · CVSS 9.0
NVD

CVE-2026-103248

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or...